AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-102938.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 5.8CVSS 4.0 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSAwaiting AnalysisModified Sep 30, 2026

Disclosure summary

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with str.splitlines() and accepts the last value for duplicate keys. An attacker who influences --prompt, VIRTUALENV_PROMPT, or configuration input can insert a recognized line boundary and additional keys, including home, causing consumers to use an attacker-selected base interpreter or corrupted environment metadata. The security impact requires prompt input from outside the operator's trust boundary; directly supplied prompt content primarily corrupts the operator's own environment. This issue is fixed in version 21.7.11.

Source-reported weakness categories

CWE-93

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-9h9j-4vrj-gf7g

Open original source · Updated Sep 30, 2026

virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection

Source severity: MEDIUM / 5.8

EcosystemPackageAffected rangeFirst patched
pipvirtualenv21.7.11
NIST National Vulnerability Database · NVD-CVE-2026-102938

Open original source · Updated Sep 30, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-09-29T17:17:19-04:00
MODIFIED 2026-09-30T16:17:25-04:00
INGESTED 2026-10-06T11:43:05-04:00